BIOC
Low
✕
Tampering with the Windows System Restore configuration
System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
ATT&CK techniques: Rootkit (T1014) Inhibit System Recovery (T1490)
Indicator:
Registry action type = set_registry_value , create_registry_key , delete_registry_value AND registry data = 1 AND registry key name = *Software\Microsoft\Windows Nt\SystemRestore\DisableSR Host host os = windows
Preventable: yes